Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/dgraph-io/dgraph: GHSA-92wq-q9pq-gw47 #1780

Closed
GoVulnBot opened this issue May 17, 2023 · 1 comment
Assignees

Comments

@GoVulnBot
Copy link

In GitHub Security Advisory GHSA-92wq-q9pq-gw47, there is a vulnerability in the following Go packages or modules:

Unit Fixed Vulnerable Ranges
github.com/dgraph-io/dgraph 23.0.0 < 23.0.0

Cross references:
No existing reports found with this module or alias.

See doc/triage.md for instructions on how to triage this report.

modules:
  - module: github.com/dgraph-io/dgraph
    versions:
      - fixed: 23.0.0
    packages:
      - package: github.com/dgraph-io/dgraph
summary: Dgraph Audit Log Encryption Vulnerability
description: |-
    ### Impact
    Existing Dgraph audit logs are vulnerable to brute force attacks due to nonce collisions.  All audit logs generated by versions of Dgraph <v23.0.0 are affected.

    ### Patches
    This issue was patched in https://github.com/dgraph-io/dgraph/pull/8323.  Dgraph users should upgrade to v23.0.0.

    ### Workarounds
    Store existing audit logs in a secure location.  For extra security, encrypt using a tool like `gpg`.

    ### References
    See https://github.com/dgraph-io/dgraph/pull/8323 for more context on the vulnerability.
cves:
  - CVE-2023-31135
ghsas:
  - GHSA-92wq-q9pq-gw47
references:
  - advisory: https://github.com/dgraph-io/dgraph/security/advisories/GHSA-92wq-q9pq-gw47
  - fix: https://github.com/dgraph-io/dgraph/pull/8323
  - web: https://github.com/dgraph-io/dgraph/releases/tag/v23.0.0
  - advisory: https://github.com/advisories/GHSA-92wq-q9pq-gw47

@julieqiu julieqiu self-assigned this May 20, 2023
@tatianab
Copy link
Contributor

tatianab commented Jun 2, 2023

Duplicate of #1781

@tatianab tatianab marked this as a duplicate of #1781 Jun 2, 2023
@tatianab tatianab closed this as completed Jun 2, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants